CVE Vulnerabilities

CVE-2008-5503

Published: Dec 17, 2008 | Modified: Apr 09, 2025
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
2.6 LOW
AV:N/AC:H/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu
LOW
root.io logo minimus.io logo echo.ai logo

The loadBindingDocument function in Mozilla Firefox 2.x before 2.0.0.19, Thunderbird 2.x before 2.0.0.19, and SeaMonkey 1.x before 1.1.14 does not perform any security checks related to the same-domain policy, which allows remote attackers to read or access data from other domains via crafted XBL bindings.

Affected Software

NameVendorStart VersionEnd Version
FirefoxMozilla*2.0.0.18 (including)
FirefoxMozilla2.0 (including)2.0 (including)
FirefoxMozilla2.0.0.1 (including)2.0.0.1 (including)
FirefoxMozilla2.0.0.2 (including)2.0.0.2 (including)
FirefoxMozilla2.0.0.3 (including)2.0.0.3 (including)
FirefoxMozilla2.0.0.4 (including)2.0.0.4 (including)
FirefoxMozilla2.0.0.5 (including)2.0.0.5 (including)
FirefoxMozilla2.0.0.6 (including)2.0.0.6 (including)
FirefoxMozilla2.0.0.7 (including)2.0.0.7 (including)
FirefoxMozilla2.0.0.8 (including)2.0.0.8 (including)
FirefoxMozilla2.0.0.9 (including)2.0.0.9 (including)
FirefoxMozilla2.0.0.10 (including)2.0.0.10 (including)
FirefoxMozilla2.0.0.11 (including)2.0.0.11 (including)
FirefoxMozilla2.0.0.12 (including)2.0.0.12 (including)
FirefoxMozilla2.0.0.13 (including)2.0.0.13 (including)
FirefoxMozilla2.0.0.14 (including)2.0.0.14 (including)
FirefoxMozilla2.0.0.15 (including)2.0.0.15 (including)
FirefoxMozilla2.0.0.16 (including)2.0.0.16 (including)
FirefoxMozilla2.0.0.17 (including)2.0.0.17 (including)
SeamonkeyMozilla*1.1.13 (including)
SeamonkeyMozilla1.0 (including)1.0 (including)
SeamonkeyMozilla1.0.1 (including)1.0.1 (including)
SeamonkeyMozilla1.0.2 (including)1.0.2 (including)
SeamonkeyMozilla1.0.3 (including)1.0.3 (including)
SeamonkeyMozilla1.0.5 (including)1.0.5 (including)
SeamonkeyMozilla1.0.6 (including)1.0.6 (including)
SeamonkeyMozilla1.0.7 (including)1.0.7 (including)
SeamonkeyMozilla1.0.8 (including)1.0.8 (including)
SeamonkeyMozilla1.0.9 (including)1.0.9 (including)
SeamonkeyMozilla1.1 (including)1.1 (including)
SeamonkeyMozilla1.1-alpha (including)1.1-alpha (including)
SeamonkeyMozilla1.1-beta (including)1.1-beta (including)
SeamonkeyMozilla1.1.1 (including)1.1.1 (including)
SeamonkeyMozilla1.1.2 (including)1.1.2 (including)
SeamonkeyMozilla1.1.3 (including)1.1.3 (including)
SeamonkeyMozilla1.1.4 (including)1.1.4 (including)
SeamonkeyMozilla1.1.5 (including)1.1.5 (including)
SeamonkeyMozilla1.1.6 (including)1.1.6 (including)
SeamonkeyMozilla1.1.7 (including)1.1.7 (including)
SeamonkeyMozilla1.1.8 (including)1.1.8 (including)
SeamonkeyMozilla1.1.9 (including)1.1.9 (including)
SeamonkeyMozilla1.1.10 (including)1.1.10 (including)
SeamonkeyMozilla1.1.11 (including)1.1.11 (including)
SeamonkeyMozilla1.1.12 (including)1.1.12 (including)
ThunderbirdMozilla*2.0.0.18 (including)
ThunderbirdMozilla2.0.0.0 (including)2.0.0.0 (including)
ThunderbirdMozilla2.0.0.4 (including)2.0.0.4 (including)
ThunderbirdMozilla2.0.0.5 (including)2.0.0.5 (including)
ThunderbirdMozilla2.0.0.6 (including)2.0.0.6 (including)
ThunderbirdMozilla2.0.0.9 (including)2.0.0.9 (including)
ThunderbirdMozilla2.0.0.12 (including)2.0.0.12 (including)
ThunderbirdMozilla2.0.0.14 (including)2.0.0.14 (including)
ThunderbirdMozilla2.0.0.16 (including)2.0.0.16 (including)
ThunderbirdMozilla2.0.0.17 (including)2.0.0.17 (including)
Red Hat Enterprise Linux 2.1RedHatseamonkey-0:1.0.9-0.25.el2*
Red Hat Enterprise Linux 3RedHatseamonkey-0:1.0.9-0.29.el3*
Red Hat Enterprise Linux 4RedHatseamonkey-0:1.0.9-32.el4*
Red Hat Enterprise Linux 4RedHatthunderbird-0:1.5.0.12-18.el4*
Red Hat Enterprise Linux 5RedHatthunderbird-0:2.0.0.19-1.el5_2*
FirefoxUbuntudapper*
FirefoxUbuntudevel*
FirefoxUbuntugutsy*
FirefoxUbuntuhardy*
Firefox-3.0Ubuntugutsy*
Firefox-3.0Ubuntuhardy*
Firefox-3.0Ubuntuintrepid*
Firefox-3.0Ubuntujaunty*
Firefox-3.0Ubuntuupstream*
IceapeUbuntugutsy*
IceapeUbuntuupstream*
Mozilla-thunderbirdUbuntudapper*
SeamonkeyUbuntuhardy*
SeamonkeyUbuntuintrepid*
SeamonkeyUbuntuupstream*
ThunderbirdUbuntudevel*
ThunderbirdUbuntugutsy*
ThunderbirdUbuntuhardy*
ThunderbirdUbuntuintrepid*
ThunderbirdUbuntujaunty*
ThunderbirdUbuntukarmic*
ThunderbirdUbuntuupstream*
Xulrunner-1.9Ubuntugutsy*
Xulrunner-1.9Ubuntuhardy*
Xulrunner-1.9Ubuntuintrepid*
Xulrunner-1.9Ubuntujaunty*
Xulrunner-1.9Ubuntuupstream*

References